🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bcaca6fc1d5abe8d437d22fc4fad17cb37eb727f84f4f07da1f98d279575e1f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: bcaca6fc1d5abe8d437d22fc4fad17cb37eb727f84f4f07da1f98d279575e1f0
SHA3-384 hash: abd6b4f9b62f7efb8ae2d4b760ed326a5fffd969cac18dba8d20de642bd379bfef3dff0cdfe6eb433d44b82e97f8c4ef
SHA1 hash: 3dd2ac97e967cac941ab0ff892f9f9dd55cb2a41
MD5 hash: 975efcfa0c3c1ff6fd019bf4fb63d5e6
humanhash: emma-thirteen-connecticut-alaska
File name:LockBit_tasca.com_28.02.22.zip
Download: download sample
Signature LockBit
File size:391'268 bytes
First seen:2022-03-03 01:45:10 UTC
Last seen:2022-04-19 21:27:41 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:JD+g2Hl65qFjZrUcEFln2ocPqECFRw35TpRd1Q4nxI8oxaZmNJ5+J9C:N+tF/9rol2ociFC53d1OXNFC9C
TLSH T1518423675C02CA20428AC85B3BC6065CCC73D55C062FAD7CADB25FB88B64DDBE0D575A
Reporter r3dbU7z
Tags:lockbit Ransom zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
950
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm cmd.exe evasive exploit explorer.exe obfuscated shell32.dll
Threat name:
Win32.Ransomware.LockBit
Status:
Malicious
First seen:
2022-03-03 01:46:11 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
23 of 27 (85.19%)
Threat level:
  5/5
Result
Malware family:
lockbit
Score:
  10/10
Tags:
family:lockbit evasion persistence ransomware
Behaviour
Interacts with shadow copies
Modifies Control Panel
Modifies registry class
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Drops file in Program Files directory
Drops file in System32 directory
Sets desktop wallpaper using registry
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Checks computer location settings
Modifies extensions of user files
Deletes shadow copies
Modifies boot configuration data using bcdedit
Lockbit
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

LockBit

zip bcaca6fc1d5abe8d437d22fc4fad17cb37eb727f84f4f07da1f98d279575e1f0

(this sample)

  
Delivery method
Distributed via web download

Comments